Security researchers at AIR Security disclosed a vulnerability last week that hit four major AI coding agents at once, Anthropic's Claude Code, OpenAI's Codex, Microsoft's GitHub Copilot, and Google's Gemini CLI. Two have been patched. Two have not. The flaw, named Plugin4Shell, doesn't target the AI models themselves. It targets the plugin marketplaces these agents pull from, and it requires nothing from the person using the tool, no click, no approval, no mistake on their part at all.
What This Actually Lets an Attacker Do
Coding agents can install plugins, skills, and extensions from community marketplaces to extend what they can do. To keep that safe, developers rely on a practice called SHA pinning: once a plugin has been reviewed and approved, it gets locked to one specific, exact version of the code, identified by a 40-character fingerprint. The promise that pin is supposed to make is simple: This agent will only ever run the exact code someone already checked and approved, nothing else, ever, unless a human deliberately reviews and approves a new version.
Think of SHA pinning as a wristband from a reviewed, trusted vendor. The agent is told: Only accept deliveries wearing this exact wristband. Plugin4Shell lets an attacker manufacture a fake wristband that looks identical to the real one, then swap out what's inside the box. The agent checks the wristband, sees it matches, and lets the package through without ever opening it to compare contents against what was actually reviewed.
Here's the part that makes this dangerous rather than just theoretically interesting: Claude Code and Codex both check for plugin updates automatically, in the background, on their own schedule. Nobody has to click update. Nobody has to approve anything. The agent periodically checks its marketplace for a new version carrying that same wristband, and if an attacker has already staged the swap, the agent pulls down the malicious version and starts running it, unattended, the next time that background check happens. The user finds out nothing changed. Their agent just quietly started running code someone else wrote, with no prompt, no warning, and no record that anyone approved it.
Once that malicious code is running, it inherits whatever access the coding agent itself already has. For a coding agent, that's typically substantial: read and write access to your codebase, visibility into environment variables and stored credentials, and in many setups, the ability to execute commands directly in development or even production environments. This isn't an attacker guessing a password or tricking someone into opening an attachment. It's an attacker getting a developer-level foothold inside your systems through a routine, automatic process nobody was watching.
Which Tools Are Fixed, and Which Aren't
AIR Security reported the flaw to all four vendors in June, giving each roughly three months before public disclosure on September 17. Anthropic patched Claude Code in version 2.1.179. OpenAI patched Codex in version 0.146.0. If you run either tool, updating to those versions or later closes the hole.
Google took a different path entirely: rather than fix Gemini CLI, it deprecated the product outright, meaning every existing installation stays vulnerable indefinitely, with Google's guidance being to migrate to its newer Antigravity agent instead, which doesn't use the same plugin marketplace architecture and isn't exposed to this particular flaw. Microsoft had not shipped a fix for Copilot as of the most recent reporting. A GitHub spokesperson has disputed that GitHub Copilot specifically is affected by Plugin4Shell attacks, a claim that sits in tension with earlier reporting naming Copilot among the affected agents, and one worth watching for clarification rather than treating as settled either way.
Why This Is Being Called a First
AIR Security describes Plugin4Shell as a first-of-its-kind AI supply-chain attack, and the distinction matters. Most AI security incidents this year have targeted the models themselves, tricking them into misbehaving through clever prompts, or the accounts and credentials around them. This one targets the trust relationship between an agent and the marketplace it pulls plugins from, a layer most security teams aren't yet monitoring closely, if at all. Because a single compromised marketplace entry can reach every agent that installed it, the potential blast radius is far wider than one company's misconfigured account.
What This Means If Your Team Uses These Tools
- If you're running Claude Code or Codex, confirm you're on version 2.1.179 or 0.146.0 respectively, or later. This is not optional cleanup, it closes an active, disclosed, zero-click hole.
- If you're running Gemini CLI, there is no patch coming. Migrating to Antigravity or another actively maintained agent isn't a convenience recommendation, it's the only way to close this specific exposure.
- If your team uses GitHub Copilot, treat the vendor's and researchers' conflicting claims as an open question, not a resolved one, and ask Microsoft directly for a current, specific answer rather than relying on secondhand reporting either way.
- More broadly, if your security team's threat model for AI coding agents stops at the model and doesn't extend to the plugin marketplaces those agents pull from automatically, this incident is the reason to extend it now, before the next one.
Sources: AI Pulse · Where This Breaks · workplaceai.ai. Plugin4Shell disclosure, technical details, and vendor patch status: AIR Security's disclosure, The Register, Help Net Security, and CyberSecurityNews, September 17-18, 2026. The GitHub Copilot dispute: The Register. Every technical detail above is attributed to its original reporting; none is a WorkplaceAI study.